LOLDocs - Sideloading in Signed Office Files
Offered By: BruCON Security Conference via YouTube
Course Description
Overview
Explore an innovative approach to phishing through "code side-loading in signed documents" in this 43-minute conference talk from BruCON Security Conference. Delve into the process of identifying vulnerabilities in Microsoft signed Office add-ins, with a focus on the Microsoft Analysis ToolPak Excel add-ins (.XLAM file type). Learn how attackers can exploit these vulnerabilities to embed malicious code without invalidating signatures, creating potential phishing scenarios. Discover the complexities involved in finding, exploiting, and weaponizing this class of vulnerabilities, as well as the challenges in implementing effective mitigations. Gain insights into the ongoing battle between increased security measures and evolving phishing techniques in the realm of Office documents.
Syllabus
07 - BruCON 0x0E - LOLDocs: Sideloading in Signed Office files - Pieter Ceelen & Dima van de Wouw
Taught by
BruCON Security Conference
Related Courses
Being a Cyberdefender - Behind the CurtainsBruCON Security Conference via YouTube Bypassing Microsoft Defender for Identity
BruCON Security Conference via YouTube A Black-Box Security Evaluation of the SpaceX Starlink User Terminal
BruCON Security Conference via YouTube Android Malware Targeting Belgian Financial Apps
BruCON Security Conference via YouTube Chasing the White Whale of Malware
BruCON Security Conference via YouTube